Data Processing Agreement
GDPR Article 28 controller-to-processor template, ready for counter-signature with Mind Architecture Group.
How to use this template
This is the v0.1 template for a controller-to-processor Data Processing Agreement (DPA) under GDPR Article 28 for engagements where Mind Architecture Group acts as the processor. The customer (you) is the controller.
To execute: print or e-sign, fill in the schedule (annex A) for the engagement, and have both parties initial every page and sign the last page. We will countersign within five business days of receipt.
For data residency, retention, or sub-processor changes that deviate from the standard schedule, request a redline at legal@mindarchitecturegroup.com before signing.
Definitions
- Agreement means the underlying commercial agreement between Controller and Processor, of which this DPA forms an integral part.
- Applicable Data Protection Law means GDPR, the UK GDPR, the CCPA / CPRA, and any other privacy law that applies to the processing of Personal Data under this Agreement.
- Controller, Processor, Personal Data, Processing, Data Subject, Supervisory Authority have the meanings given in Article 4 GDPR.
- Sub-processor means any third party engaged by Processor to process Personal Data on behalf of the Controller.
- Standard Contractual Clauses (SCCs) means the 2021/914 EU standard contractual clauses for the transfer of personal data to third countries.
- Security Incident means any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
Subject matter and duration of processing
1.1 Subject matter. Processor will process Personal Data only on the documented instructions of Controller, for the purposes described in Annex A (Schedule of Processing) and for no other purpose.
1.2 Duration. Processing continues for the term of the Agreement. On termination, Processor will return or delete Personal Data per clause 9.
1.3 Nature and purpose. As specified in Annex A. Typical purposes include: operating the Mind Architecture consulting and learning platform, generating AI-assisted reports, communicating with named contacts, and producing compliance artefacts.
Categories of data and data subjects
2.1 Categories of data subjects. Controller's employees, contractors, learners, clients, prospects, and other individuals whose Personal Data Controller chooses to upload.
2.2 Types of Personal Data. As specified in Annex A. Standard scope includes: name, role, organisation, work email, work phone, free-text answers to assessment questions, course progress, and engagement metadata. Sensitive (Art. 9) data is in scope only if Annex A explicitly says so and only with explicit, separately recorded consent.
2.3 No special-category data by default. If the engagement touches mental-health, sports-psychology, or other potentially special-category data, Annex A must name the lawful basis (typically Art. 9(2)(a) explicit consent) and the Controller must surface a consent checkbox to the data subject before submission.
Documented instructions and prohibited processing
3.1 Documented instructions only. Processor will process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by EU or Member State law. In that case Processor will inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 No selling, no profiling for automated decisions.Processor will not sell Personal Data, will not share it with third parties for their own purposes, and will not subject it to automated decision-making with legal effects on data subjects (Art. 22) without an explicit, signed addendum.
3.3 No training on Customer data. Where the underlying AI provider offers a no-training-on-customer-data configuration, Processor will keep that configuration enabled.
Confidentiality (Art. 28(3)(b))
Processor will ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data is role-limited; the production database credentials are held only by named engineers and rotated on a documented schedule.
Security of processing (Art. 32)
Processor will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Current standard measures:
- Encryption in transit. HTTPS / TLS 1.2+ on every public endpoint, HSTS with preload flag.
- Encryption at rest. Database and object storage use the platform provider's default AES-256 at-rest encryption.
- Access control. Supabase Row Level Security on every user-keyed table; anon role revoked for sensitive tables.
- Bot and abuse protection. Cloudflare Turnstile on all public forms that accept Personal Data.
- Application security. CSP, X-Frame-Options DENY, X-Content-Type-Options nosniff, Permissions-Policy, COOP, CORP at the app layer; weekly dependency-vulnerability scan in CI.
- Human-approval gate. AI-generated reports are held in
awaiting_reviewuntil a human operator marks themclient_visible. They are never shown to a client without that sign-off. - Logging. Auth failures, role changes, and data exports are logged. Logs are retained for 90 days.
The full control set and operating evidence is published in the compliance dashboard (the sub-processor register is annexed to each signed DPA as Annex B and is not currently published at a public URL).
Sub-processors (Art. 28(2) and 28(4))
7.1 General authorisation. Controller gives Processor general authorisation to engage the sub-processors listed in Annex B of the executed Agreement. The current live list (with purpose, region, DPA status, and certifications for each) is annexed to each signed DPA and is not currently published at a public URL.
7.2 Notice period for new sub-processors. Processor will give Controller at least 30 days' written notice before engaging a new sub-processor. Controller may object on reasonable data protection grounds within the notice period. If Controller objects and Processor cannot accommodate the objection, either party may terminate the affected services without penalty.
7.3 Flow-down obligations. Processor will impose on each sub-processor, by written contract, data protection obligations no less protective than those in this Agreement. Processor remains fully liable to Controller for the performance of each sub-processor's obligations.
7.4 International transfers. Where a sub-processor is established outside the EEA, UK, or an adequacy-decision country, Processor will use the EU Standard Contractual Clauses (Module 2 controller-to-processor) or the UK International Data Transfer Addendum as the transfer mechanism, and will make the executed clauses available to Controller on request.
Assistance with data subject rights (Art. 28(3)(e))
Taking into account the nature of the processing, Processor will assist Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of Controller's obligation to respond to requests for exercising data subject rights (access, rectification, erasure, restriction, portability, objection, automated decision-making).
Current standard assistance: a self-service data export and delete flow at /me/data (Phase 2 work) and a manual intake at privacy@mindarchitecturegroup.com with a 30-day response target.
Security incident notification (Art. 33(2))
9.1 Notification timing. Processor will notify Controller without undue delay, and in any case within 48 hours, after becoming aware of a Security Incident affecting Personal Data processed under this Agreement.
9.2 Initial content. The notification will describe the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its possible adverse effects.
9.3 Cooperation. Processor will cooperate with Controller in fulfilling Controller's own notification obligations to Supervisory Authorities (Art. 33) and to data subjects (Art. 34) where applicable. Processor will not publicly disclose a Security Incident involving Controller's Personal Data without Controller's prior written consent, except as required by law.
Return or deletion at end of processing (Art. 28(3)(g))
On termination of the Agreement, Processor will, at Controller's choice, return all Personal Data to Controller or delete it, including all copies, unless EU or Member State law requires storage of the Personal Data. Processor will confirm deletion in writing within 30 days of termination.
Where Controller requests return, Processor will deliver the data in a commonly used, machine-readable format (JSON or CSV) within 30 days of the request.
Audits and inspections (Art. 28(3)(h))
Processor will make available to Controller all information necessary to demonstrate compliance with the obligations in this Agreement and in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller.
12.1 Standing evidence. Processor publishes an ongoing compliance register (the compliance dashboard at /dashboard when signed in as an operator, or via a redacted public summary on request) covering security headers, captcha enforcement, dependency scans, AI-report approval state, and the sub-processor list.
12.2 On-demand audit. Controller may request one on-site or remote audit per calendar year on 30 days' written notice. Controller bears its own costs; Processor bears its own costs. If the audit reveals a material breach, the breaching party bears both parties' reasonable audit costs.
Liability
The parties' liability under this DPA is subject to the limitation of liability in the underlying Agreement, except where such limitation is prohibited by Applicable Data Protection Law (including Art. 82 GDPR, which is not waivable).
Governing law and order of precedence
This DPA is governed by the law of the jurisdiction set out in the underlying Agreement. In the event of any conflict between this DPA and the underlying Agreement on data protection matters, this DPA prevails.
Where mandatory provisions of Applicable Data Protection Law apply, those provisions prevail over any conflicting term in this DPA.
Annex A — Schedule of Processing
To be completed per engagement. Default values below.
- Controller: [Customer legal name and address]
- Processor: Mind Architecture Group, [registered address]
- Subject matter: operation of the Mind Architecture consulting / learning platform for the Controller's named engagement.
- Duration: term of the underlying commercial agreement.
- Nature: SaaS — consulting and learning delivery; AI-assisted report generation; communications with named contacts.
- Purpose: the purposes described in the Statement of Work or equivalent document, including discovery assessment, report generation, course delivery, and progress tracking.
- Categories of data subjects: Controller's employees, contractors, learners, and named client contacts.
- Types of Personal Data: name, role, organisation, work email, work phone, free-text answers to assessment questions, course progress, engagement metadata. Art. 9 special-category data: only if explicitly agreed below.
- Art. 9 scope (if any): [yes / no — if yes, describe scope and the explicit-consent capture mechanism used]
- Processing region: [EU / US / other — per the customer's data residency election]
- Retention: engagement data 24 months from last activity unless earlier deletion is requested.
- Sub-processor list: see Annex B (annexed to the executed Agreement).
Annex B — Sub-processor list
The authoritative sub-processor list is annexed to each signed Agreement. Each entry lists the sub-processor's purpose, the categories of Personal Data shared, the region of processing, the DPA status (countersigned / standard terms / under review), and the certifications on file. Material changes to this list follow the 30-day notice rule in clause 7.2.
